Software Supply Chain Security (Part 1)
In my last post, we talked about the cloud and application security ecosystem. I shared the six major market categories within this rapidly evolving cloud ecosystem. Today, I’d like to focus on the newest and fastest-growing category among those six areas. In less than 4-years, Software Supply Chain Security (SSCS) security has quickly emerged as the buzziest sector within AppSec. The hype was at its peak last year but has gradually faded down recently. Hence, this is a good time to focus on this topic. I’ve done extensive research into this market. Last year, I co-wrote a deep-dive into the software supply chain in collaboration with Clint Gibler at the tldrsec. We wrote an SSCS part 1 and SSCS part 2 series, but I never got to share this knowledge with my readers. Today, I’ll focus on SSCS, the latest developments since that last report, and, more importantly, discuss some of the less-hyped frameworks and underlooked vendors within this market over a two-part series. I wrote this rep
Software Supply Chain Security Deep-Dive (Part 1) The fastest growing category of App & Cloud Security. This deep dive piece explains the buzz around the sector and sheds a spotlight on some new vendors SACR and Nipun Gupta Apr 10, 2024 26 1 Share In my last post, we talked about the cloud and application security ecosystem. I shared the six major market categories within this rapidly evolving cloud ecosystem. Today, I’d like to focus on the newest and fastest-growing category among those six areas. In less than 4-years, Software Supply Chain Security (SSCS) security has quickly emerged as the
Explore this link on the map →saved by
related reading
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- State of DevSecOps | Datadogdatadoghq.com
- Shortcuts Sell - by James Berthoty - Latio Pulsepulse.latio.tech
- Report: Taking The Fight To The Cloud | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- Report: Taking The Fight To The Cloud | A Contrary Research Deep Dive | Contrary Researchresearch.contrary.com
- OpenSSF Scorecardsecurityscorecards.dev
- We should all be using dependency cooldownsblog.yossarian.net
- See No Evillogicmag.io
- How Wiz Became the Fastest Software Company to Hit $500M & Its Path to $1Bsoftwareanalyst.substack.com
- Sandwich Bill of Materials | Andrew Nesbittnesbitt.io
- Understanding SOC 2 Compliance for Containers and Cloud | Sysdigsysdig.com